Event details
During Microsoft Secure you learned about the latest innovations around Microsoft's SIEM and XDR solution. Join this Ask Microsoft Anything (AMA) session to get your questions about Microsoft Sentine...
Trevor_Rusher
Updated Dec 27, 2024
TobyMcG
Mar 31, 2023Copper Contributor
Further to the Defender AV Sample Submission process, we understand that the M365 Defender AIR (Automated Investigations and Response) service can also request files be sent for analysis based on telemetry it's correlated.
When AIR requests a file be sent for Sample Submission, what is the logical flow between AIR and Defender AV for requesting and sending the suspicious file to the blob, and getting a response back? I.E:
Does Defender AV send the sample, get a response and then inform the AIR service?
Alternatively, does AIR request that Defender AV send the file for analysis, but AIR receives the response directly from the blob before instructing Defender AV to allow or block the file?
If AIR gets notified directly, how is this handled with the anonymisation process of submitted files in the previous question?
Is there any documentation on the data destruction process of samples held in the blobs following the Sample Submission of Cloud Delivered Protection?
Ed Fisher
Microsoft
Apr 13, 2023There is definitely too much in this series of questions to cover adequately in this asynchronous chat format. Please engage your account team who can better assist you.